Security at DocFila

Your documents are sensitive. DocFila uses managed-cloud encryption, least-privilege controls, malware scanning, tamper-evident signing evidence, and public vulnerability reporting.

Encryption & data protection

🔐 AES-256 at rest

Every document, signature, embedding, and audit log is encrypted at rest with AES-256 by Google Cloud's default encryption. The text DocFila extracts from your documents is encrypted again, field by field, with per-account keys before it is stored. DocFila's servers can derive those keys, so this is not end-to-end encryption.

🔒 TLS in transit

Production traffic uses HTTPS with HSTS. Exact protocol negotiation depends on the managed hosting edge and supported client.

🗝️ Key management

Google-managed keys protect stored cloud data. Customer-managed keys are on the roadmap and not available today.

🛡️ Vault: your key, if you choose it

Vault items marked Encrypted, or stored with zero-knowledge mode on, are encrypted on your device with AES-256-GCM before upload, with a key DocFila's servers never receive. Items left at Standard are protected by the vault lock and Google's at-rest encryption only.

What is encrypted, and what is not

Stated field by field, so nobody has to infer it. DocFila is not end-to-end encrypted: our servers can read your document text, because search and automation run there. Only the Vault offers a key we never receive.

DataProtectionWho can read it
Everything, in transitTLS (HTTPS)The two ends of the connection
Everything, at restAES-256 by Google Cloud, Google-managed keys (no customer-managed keys)Google's infrastructure and DocFila's servers
Text extracted from your documents, AI summaries, entities found in them, search chunksAlso AES-256-GCM, field by field, with a key for your account derived on our serverYou, and DocFila's servers (not end-to-end)
Search index wordsReplaced by keyed HMAC-SHA256 tokens; no word is storedNo one can read a word back
Vault items marked Encrypted, or in zero-knowledge modeAES-256-GCM on your device before uploadOnly a device that holds the key, or someone with the item's password or recovery phrase
The uploaded file itself (PDF, image, Word)At-rest encryption by Google onlyYou, and DocFila's servers
Titles, file names, tags, folders, dates, sizes, most extracted fields, DocFila Studio chat history, Vault Standard items and all vault item namesAt-rest encryption by Google onlyYou, and DocFila's servers
Content you send to an AI featureTLS to Google's Gemini API or Vertex AIGoogle, under its terms for those services — see AI data handling

The engineering version of this table — with the code and the automated tests behind every row — is kept in DocFila's repository as docs/security/ENCRYPTION.md and is shared in full during a security review.

Compliance & certifications

📋 Assurance status

DocFila does not currently claim SOC 2, ISO 27001, or HIPAA certification. Implemented controls and mappings are not independent attestations.

🇪🇺 Privacy program

Retention, deletion, legal-hold, access, and audit controls support customer privacy obligations. Contractual terms apply only when executed.

🏥 Regulated workloads

Regulated data requires an architecture and legal review before use. Do not upload PHI unless the required agreement has been executed.

📐 Control mappings

Control mappings support internal readiness and buyer review. Certification will be stated only after an independent auditor issues a current report.

AI & privacy

🚫 No training on your data

DocFila does not train, fine-tune, or evaluate any model on your documents, and builds no dataset from them. DocFila's AI server functions do not store your request or the answer, and provider error bodies are never logged. Results a feature is meant to keep — a saved summary, your DocFila Studio chat history — stay in your account until you delete them. The named provider and its terms: AI data handling.

🤖 AI you can switch off

Each device has an AI switch: On (the default), Local only, or Off. While it is On, document content goes to Google (Gemini API) when you use an AI feature, and each saved document's text (up to roughly the first 9,000 characters) goes to Google Vertex AI to build your search index. In Local only or Off, no document content is sent to any AI service.

👀 No human review of content

DocFila employees do not read your documents to improve products. Automated quality monitoring uses metadata only.

🇨🇳 No PRC dependencies

No model providers, infrastructure, or sub-processors in jurisdictions with mandatory data access laws (PRC, Russia, Iran, North Korea).

Operational security

🔍 Release validation

Automated rules, secret, artifact, API-contract, malware, and regression gates run before deployment. Independent testing is reported only when completed.

📊 Monitoring

Production telemetry and provider alerts support incident detection. Coverage and response commitments are documented in the customer's support terms.

🔄 Backup & recovery

Database delete protection is on, and Google replicates stored data across zones. Point-in-time recovery, managed backups, and a tested restore are not in place yet, so no RPO or RTO is offered.

🛂 Least privilege

One person, the founder, holds production access, and every deploy, rules change, and secret rotation goes through them. What each app user can read and write is enforced by database and storage security rules, tested before release.

Responsible disclosure

Found a security issue? We want to know. Email security@docfila.com with details. The contact is also published at /.well-known/security.txt. We confirm receipt and triage every report by severity.

Security reports are triaged by severity. Reward or safe-harbor terms apply only when confirmed in writing for the submitted report.

Want a deeper security review?

Business and Enterprise prospects can request architecture documentation, control mappings, API documentation, and current engineering test evidence.

Request Documents